SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsFocusing on the behaviors macOS infostealers use to exfiltrate data is important for implementing effective defenses.
This paper analyzes macOS infostealers and their reliance on native system utilities. The use of specific command-line options and arguments should be predictable and detectable with proper analysis. Infostealer samples were run in a macOS sandbox environment to analyze how specific malware families exfiltrate data. Analysis shows that multiple malware families use the native utility, curl, commonly for exfiltration. Command-line options and arguments vary across malware families, indicating that infostealer exfiltration can be detected and triaged when detections are tailored to find exfiltration activity. This can lead to multiple approaches for security teams when developing detection rules and modeling cyber threats.


















